cPanel / WHM Plugin
The IPAbuse cPanel plugin checks every incoming connection against the IPAbuse reputation API and blocks high-risk IPs via CSF (ConfigServer Security & Firewall) before they reach your server.
Requirements
- cPanel & WHM 102 or later
- CSF (ConfigServer Security & Firewall) installed
- Root SSH access
- IPAbuse API key
- Outbound HTTPS to
api.ipabuse.org
Install
cURL
# Download and run the installer as root
curl -fsSL https://downloads.ipabuse.org/plugins/cpanel/install.sh | bashThe installer registers a cPanel hook that fires on each incoming connection, installs the IPAbuse WHM plugin interface, and adds a cron job to keep the local blocklist cache warm.
Configure
Edit /etc/ipabuse/config.ini with your settings:
/etc/ipabuse/config.ini
[ipabuse]
api_key = YOUR_API_KEY
risk_threshold = 50
block_ttl = 3600
categories = SPAM,SSH_BRUTE_FORCE,WEB_ATTACK
log_file = /var/log/ipabuse/blocks.log| Key | Default | Description |
|---|---|---|
| api_key | — | Your IPAbuse API key (required) |
| risk_threshold | 50 | Block IPs with a reputation score below this value (0–100) |
| block_ttl | 3600 | Seconds to keep an IP in the local deny list before re-checking |
| categories | (all) | Comma-separated list of abuse categories to act on |
| log_file | /var/log/ipabuse/blocks.log | Path to the block log |
Restart the service after editing:
cURL
service ipabuse-hook restartUninstall
cURL
curl -fsSL https://downloads.ipabuse.org/plugins/cpanel/uninstall.sh | bashNext steps
- All Plugins
- Authentication — rotate your API key.